From a131649be83af6c8243f239d44e59f2307e0a0cd Mon Sep 17 00:00:00 2001 From: mether049 Date: Wed, 11 Nov 2020 20:31:07 +0900 Subject: [PATCH] Update malware-tech_ref_and_memo.md --- malware-tech_ref_and_memo.md | 1 + 1 file changed, 1 insertion(+) diff --git a/malware-tech_ref_and_memo.md b/malware-tech_ref_and_memo.md index b938beb..bf297e1 100644 --- a/malware-tech_ref_and_memo.md +++ b/malware-tech_ref_and_memo.md @@ -103,6 +103,7 @@ to do... **ref:**
[Knockin’ on Heaven’s Gate – Dynamic Processor Mode Switching(2012-09)](http://rce.co/knockin-on-heavens-gate-dynamic-processor-mode-switching/)
[The 0x33 Segment Selector (Heavens Gate)](https://www.malwaretech.com/2014/02/the-0x33-segment-selector-heavens-gate.html)
+[WOW64!Hooks: WOW64 Subsystem Internals and Hooking Techniques](https://www.fireeye.com/blog/threat-research/2020/11/wow64-subsystem-internals-and-hooking-techniques.html)
## API obfuscation [A Museum of API Obfuscation on Win32](https://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/a_museum_of_api_obfuscation_on_win32.pdf)